2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26237 | MEDIUM | 5.5 | 0.2% | Oct 6, 2022 | The default privileges for the running service Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and p... |
| CVE-2022-22503 | MEDIUM | 6.1 | 0.6% | Oct 6, 2022 | IBM Robotic Process Automation 21.0.0 could allow a remote attacker to hijack the clicking action of the victim. By pers... |
| CVE-2022-42247 | MEDIUM | 6.1 | 2.5% | Oct 3, 2022 | pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This v... |
| CVE-2022-42306 | MEDIUM | 5.5 | 0.2% | Oct 3, 2022 | An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can... |
| CVE-2022-42300 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server... |
| CVE-2022-41427 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in mp4mux. |
| CVE-2022-41426 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_AtomFactory::CreateAtomFromStream function in mp4s... |
| CVE-2022-41425 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in... |
| CVE-2022-41424 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_SttsAtom::Create function in mp42hls. |
| CVE-2022-41423 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a segmentation violation in the mp4fragment component. |
| CVE-2022-41420 | MEDIUM | 5.5 | 0.3% | Oct 3, 2022 | nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component |
| CVE-2022-41419 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt bina... |
| CVE-2022-3132 | MEDIUM | 4.8 | 0.6% | Oct 3, 2022 | The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2022-3128 | MEDIUM | 4.8 | 0.5% | Oct 3, 2022 | The Donation Thermometer WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could al... |
| CVE-2022-3124 | MEDIUM | 5.3 | 6.2% | Oct 3, 2022 | The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files f... |
| CVE-2022-2839 | MEDIUM | 5.4 | 0.4% | Oct 3, 2022 | The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJA... |
| CVE-2022-2763 | MEDIUM | 4.8 | 0.6% | Oct 3, 2022 | The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow... |
| CVE-2022-2628 | MEDIUM | 4.8 | 0.5% | Oct 3, 2022 | The DSGVO All in one for WP WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could a... |
| CVE-2022-40922 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a de... |
| CVE-2022-40123 | MEDIUM | 6.5 | 1.0% | Oct 3, 2022 | mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor... |
| CVE-2022-32173 | MEDIUM | 5.4 | 0.5% | Oct 3, 2022 | In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security rol... |
| CVE-2022-36551 | MEDIUM | 6.5 | 5.1% | Oct 3, 2022 | A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.... |
| CVE-2022-40923 | MEDIUM | 6.5 | 0.6% | Sep 30, 2022 | A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a... |
| CVE-2022-35155 | MEDIUM | 6.1 | 2.6% | Sep 30, 2022 | Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s... |
| CVE-2022-20945 | MEDIUM | 6.5 | 0.4% | Sep 30, 2022 | A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now